Skip to content

v0.1.0 — Initial public release

Choose a tag to compare

@jamesbower jamesbower released this 09 Sep 16:26
· 10 commits to main since this release

Initial public release of Detect-Forge — an AI-native detection-engineering toolkit. One install, one config, one CI step.

Install

pip install detect-forge

Highlights

  • stale — score Sigma/Elastic rules for ATT&CK technique staleness (timestamp drift, semantic drift, opt-in LLM diff proposals).
  • coverage — map rules to the ATT&CK matrix (full/shallow/gap) with CTID-weighted priority gating and Navigator export.
  • backtest — adversarial replay against the bundled Mordor corpus with Sigma + Elastic (EQL/KQL) matchers and two CI gates.
  • audit — one-step composite gate over stale + coverage + backtest.
  • Ships as a PEP 561 typed package; runs as a GitHub Actions CI gate. No data leaves your environment.

See the CHANGELOG for the full list, including the correctness and security hardening in this release.

Full metadata: https://github.com/jamesbower/Detect-Forge/blob/v0.1.0/README.md